ZeroHour

CVE-2026-51662

moderate

Unauthenticated information disclosure in TOTOLINK T6 router

CVSS 3.1
7.5 high
EPSS
<1%p31
Published
()
Modified
AI analysis

TOTOLINK T6 routers running firmware 4.1.5cu.748_B20211015 have an improper access control flaw (CWE-284) in the getCloudSrvCheckStatus function of the device's web management interface. An unauthenticated attacker can trigger it by sending a crafted POST request to the /cgi-bin/cstecgi.cgi endpoint over the network. Successful exploitation discloses the router's cloud firmware check status information only; the CVSS 3.1 vector (C:H/I:N/A:N) indicates no impact on data integrity or availability. Only the TOTOLINK T6 on the named firmware build is identified in the advisory, and whether other firmware versions are affected is not stated. No public proof-of-concept, CISA KEV listing, or confirmed in-the-wild exploitation is known, and the 0.4% EPSS suggests low near-term exploitation risk.

What to do: Do not expose the T6's web management interface to the WAN (avoid port-forwarding ports 80/443 to the router), and restrict remote management with firewall rules if it is needed. Check the running firmware version in the router's administration page and upgrade to the latest firmware TOTOLINK publishes for the T6 when available. Given the information-disclosure-only impact, absence of a known PoC, and the 0.4% EPSS, treat this as routine hardening rather than an emergency.

Affected
TOTOLINK T6 wireless router4.1.5cu.748_B20211015 (version named in the advisory; scope of other builds not stated)
Estimated exposure
moderate≈1,000–10,000 internet-exposed TOTOLINK T6 devices — Public internet scans routinely show tens of thousands of TOTOLINK routers exposed online, but this flaw is limited to one model at one specific firmware build, so only a small slice — plausibly a few thousand devices — is likely exposed…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Incorrect access control in the getCloudSrvCheckStatus function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to obtain cloud firmware check status information via sending a crafted POST request to /cgi-bin/cstecgi.cgi.

Weakness
CWE-284
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

In the news

No ingested article mentions this CVE yet.